– The location is the following: • http://finitolaco.ru:8080/forum/links/colum********** It is saved on the local hard drive under: %temporary internet files%\calc[1].exe Furthermore this file gets executed after it was fully downloaded. Further investigation pointed out that this file is malware, too. Detected as: TR/Agent.FQR